{"id":540,"date":"2009-07-11T17:13:16","date_gmt":"2009-07-11T10:13:16","guid":{"rendered":"http:\/\/deepquest.code511.com\/blog\/?p=540"},"modified":"2009-07-11T17:47:50","modified_gmt":"2009-07-11T10:47:50","slug":"vacation-hacking","status":"publish","type":"post","link":"https:\/\/deepquest.code511.com\/blog\/2009\/07\/vacation-hacking\/","title":{"rendered":"Vacation hacking"},"content":{"rendered":"<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">Cybercriminals are targeting travelers by creating phony Wi-Fi hot spots in airports, in hotels, and even aboard airliners.<br \/>\nVacationers on their way to fun in the sun, or already there, think they&#8217;re using designated Wi-Fi access points. But instead, they&#8217;re signing on to fraudulent networks and hand-delivering everything on their laptops to the crooks.<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; color: #000000; padding: 0px;\"><!--more--><span style=\"color: #888888;\">In 2008, Silicon Valley-based AirTight Networks, a wireless security company, sent a team of &#8220;white-hat&#8221; hackers \u2014 good guys who try to thwart &#8220;black hat&#8221; hackers \u2014 around the world on an international airport study.<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">They checked the Wi-Fi networks at 27 airports \u2014 20 in the U.S., five in Asia and two in Europe \u2014 and the results were not good.<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">At John F. Kennedy International Airport in New York, the baggage-handling system was being run on an insecure network. At other airports, ticketing systems were similarly exposed.<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">And everywhere they looked, they found fake Wi-Fi hot spots set up by hackers phishing for suckers \u2014 and there were plenty of suckers to be had.<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">&#8220;We found a lot of people using insecure Wi-Fi,&#8221; says AirTight investigator Rick Farina, &#8220;and people engaged in all sort of dangerous activity \u2014 checking their e-mail, doing their banking, buying stock. These are not the kinds of thing you want to be doing on public Wi-Fi.&#8221;<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">And according to their study, even the &#8220;secure&#8221; networks weren&#8217;t all too safe.<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">Eighty percent of the private Wi-Fi networks at airports surveyed by Airtight were secured by the aging Wired Equivalent Privacy (WEP) protocol, which was cracked back in 2001.<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">Almost as many \u2014 77 percent \u2014 of the networks they surveyed were actually private, peer-to-peer networks, meaning they weren&#8217;t official hotspots. Instead, they were running off someone else&#8217;s computer.<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">In response to the rise in vacation hacking, some companies are beginning to tighten up security.<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">When AirTight&#8217;s Farina alerted American Airlines to vulnerabilities in its system earlier this year, the airline took action.<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">&#8220;I can&#8217;t tell you what they did,&#8221; says Farina, &#8220;but their Wi-Fi is safer.&#8221;<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">JetBlue also says it has taken appropriate steps.<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">&#8220;Phishing is a risk that exists anywhere there are wireless services available, which is pretty much everywhere these days,&#8221; says JetBlue spokesman Bryan Baldwin.<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; padding: 0px;\"><span style=\"color: #888888;\">&#8220;At our Terminal 5 at JFK, where we offer free Wi-Fi, we have measures in place to minimize risks for our customers,&#8221; he said. &#8220;We&#8217;d prefer not to go into detail about the specifics of those measures, because the details could be used by clever hackers against the defenses.&#8221;<\/span><\/p>\n<p style=\"text-align: left; margin-top: 0px; margin-right: 0px; margin-bottom: 1em; margin-left: 0px; font-size: 1em; color: #000000; padding: 0px;\"><span style=\"color: #888888;\">A spokesman for the Marriott hotel chain would give only a terse statement:<br \/>\n&#8220;When it comes to online security, Marriott has worked diligently to protect our guests.&#8221;One thing all security experts agree on: When it comes to hackers, the best defense is a good offense.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybercriminals are targeting travelers by creating phony Wi-Fi hot spots in airports, in hotels, and even aboard airliners. Vacationers on their way to fun in the sun, or already there,&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[3],"tags":[11],"class_list":["post-540","post","type-post","status-publish","format-standard","hentry","category-security","tag-hacking"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4bBYZ-8I","_links":{"self":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/540","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/comments?post=540"}],"version-history":[{"count":7,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/540\/revisions"}],"predecessor-version":[{"id":547,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/posts\/540\/revisions\/547"}],"wp:attachment":[{"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/media?parent=540"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/categories?post=540"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/deepquest.code511.com\/blog\/wp-json\/wp\/v2\/tags?post=540"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}